How to Create a Detection Rule in Elastic SIEM

Опубликовано: 15 Июнь 2026
на канале: Olivebranch
11,981
87

This video will show the process of creating a Query-based rule in Elastic SIEM, which searches the defined indices and creates an alert when a document matches the rule’s query.

Link to the example rule created in the video https://gist.github.com/austinsonger/...

If you have any additional questions on the video you can join my slack group for this channel.
http://bit.ly/Songertech-Slack